Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Mar 2025G@S Telecomunicazioni di Losito LuciaG@S Telecomunicazioni di Losito Lucia was fined EUR 15,000 by the Garante. The case concerned the unauthorized activation of a fixed-line telephone offer, which breached data protection rules.ITGaranteGDPR€15,000
20 Mar 2008GS S.p.A.GS S.p.A. was fined for collecting personal data in connection with a loyalty card program without providing adequate notice to data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
11 Apr 2024GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€10,000
21 Jun 2021GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules.ESAEPDGDPR€200,000
09 Nov 2017GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands.ITGaranteGDPR€96,000
17 Mar 2016Gruppo Scuole s.r.l. – Istituto Giuseppe Mazzini di AvezzanoGruppo Scuole s.r.l. was fined by the Garante for collecting personal data through its website without providing the required privacy notice and without obtaining consent. The authority found violations of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€2,400
23 Mar 2023Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data.ITGaranteGDPR€10,000
15 Nov 2012Gruppo Ro.Ri. s.r.l.The Garante fined Gruppo Ro.Ri. s.r.l. 24,000 EUR for inadequate data protection measures linked to its video surveillance systems. The company also failed to provide proper information to data subjects as required by the privacy code.ITGaranteGDPR€24,000
15 Nov 2012Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code.ITGaranteGDPR€25,000
13 Jul 2016Gruppo Nadine s.r.l.Gruppo Nadine s.r.l. was fined by the Garante in the amount of 2,400 EUR for inadequate notices in its surveillance system. The notices did not include the name of the data controller, contrary to the privacy code requirements.ITGaranteGDPR€2,400
10 Mar 2011Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules.ITGaranteGDPR€8,000
24 Jan 2013Gruppo Finelco s.p.a.Gruppo Finelco s.p.a. was fined EUR 52,000 by the Garante for processing personal data without providing adequate information to data subjects. The company also failed to notify the Garante about profiling activities carried out through its websites.ITGaranteGDPR€52,000
19 May 2016GRUPO YAMM COMIDA A DOMICILIO, S.L.GRUPO YAMM COMIDA A DOMICILIO, S.L. was fined by the AEPD €1,400 for sending unsolicited commercial emails to a complainant despite requests to stop. The case concerns a breach of the LSSI rules on marketing communications.ESAEPDePrivacy€1,400
01 Jan 2016GRUPO YAMM COMIDA A DOMICILIO S.L.The entity was fined for sending unsolicited commercial emails and for failing to honor unsubscribe requests. This constituted a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,700
29 Nov 2019GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€2,500
13 Jul 2022GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR.ESAEPDGDPR€50,000
17 Mar 2022GRUPO TECNOPOLE FABRICACIÓN Y MONTAJES, S.L.The company was fined by the AEPD €800 for sending an unsolicited commercial email without the required consent. The breach concerned Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€800
26 Mar 2013GRUPORUM RESPUESTA DIRECTA, S.L.GRUPORUM RESPUESTA DIRECTA, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The conduct breached Article 21.1 of the LSSI, which requires prior consent for direct marketing by email.ESAEPDePrivacy€1,800
01 Jan 2014GRUPOPSCOM, SCPGRUPOPSCOM, SCP was fined 6,300 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€6,300
21 Mar 2014GRUPOPSCOM SCPGRUPOPSCOM SCP was fined EUR 6,000 by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€6,000